Device Security Analysis
Clinic front-desk workstation: default-account guessing and an after-hours copy
- Units 2, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, a front-desk workstation at Riverbend Family Clinic (IP address 192.0.2.53), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.5 | 192.0.2.53 | Inbound | 22 | SSH |
| 2 | Allow | 192.0.2.0/24 | 192.0.2.53 | Inbound | 5900 | VNC |
| 3 | Allow | ALL | 192.0.2.53 | Inbound | 3389 | RDP |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question
Source 2: Authentication log (sudo tail -n 13 /var/log/auth.log)
| Line | Entry |
|---|---|
| 1 | Oct 15 07:58:02 frontdesk3 gdm: session opened for user kpatel on console |
| 2 | Oct 15 12:41:10 frontdesk3 xrdp-sesman[1310]: Login failed for user administrator from 198.51.100.200 |
| 3 | Oct 15 12:41:11 frontdesk3 xrdp-sesman[1311]: Login failed for user admin from 198.51.100.200 |
| 4 | Oct 15 12:41:12 frontdesk3 xrdp-sesman[1312]: Login failed for user root from 198.51.100.200 |
| 5 | Oct 15 12:41:13 frontdesk3 xrdp-sesman[1313]: Login failed for user guest from 198.51.100.200 |
| 6 | Oct 15 12:41:14 frontdesk3 xrdp-sesman[1314]: Login failed for user user from 198.51.100.200 |
| 7 | Oct 15 12:41:15 frontdesk3 xrdp-sesman[1315]: Login failed for user test from 198.51.100.200 |
| 8 | Oct 15 12:41:16 frontdesk3 xrdp-sesman[1316]: Login failed for user support from 198.51.100.200 |
| 9 | Oct 15 12:41:17 frontdesk3 xrdp-sesman[1317]: Login failed for user frontdesk from 198.51.100.200 |
| 10 | Oct 15 13:05:44 frontdesk3 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.60 DST=192.0.2.53 PROTO=TCP DPT=22 |
| 11 | Oct 15 13:06:10 frontdesk3 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.31 DST=192.0.2.53 PROTO=TCP DPT=445 |
| 12 | Oct 15 13:20:31 frontdesk3 sshd[1402]: Accepted publickey for itadmin from 192.0.2.5 port 50410 ssh2 |
| 13 | Oct 15 13:21:05 frontdesk3 sudo: itadmin : TTY=pts/0 ; PWD=/home/itadmin ; USER=root ; COMMAND=/usr/bin/apt upgrade |
Source: Hypothetical device records written for this practice question
Source 3: File access and device log (sudo tail -n 12 /var/log/audit/file_access.log)
| Line | Entry |
|---|---|
| 1 | Oct 15 08:03:15 frontdesk3 audit: user=kpatel opened /srv/records/schedule_today.csv |
| 2 | Oct 15 11:47:52 frontdesk3 audit: user=kpatel opened /srv/records/schedule_today.csv |
| 3 | Oct 15 16:58:40 frontdesk3 audit: user=kpatel opened /srv/records/schedule_today.csv |
| 4 | Oct 15 17:31:02 frontdesk3 gdm: session closed for user mlee |
| 5 | Oct 15 19:48:30 frontdesk3 kernel: usb 1-2: new high-speed USB device number 5 using xhci_hcd |
| 6 | Oct 15 19:48:31 frontdesk3 kernel: usb-storage 1-2:1.0: USB Mass Storage device detected |
| 7 | Oct 15 19:48:33 frontdesk3 udisks: Mounted /dev/sdb1 at /media/kpatel/TRANSFER |
| 8 | Oct 15 19:50:02 frontdesk3 audit: user=kpatel opened /srv/records/Card_Numbers_MASTER.xlsx |
| 9 | Oct 15 19:50:02 frontdesk3 honeypot-watch: ALERT decoy file Card_Numbers_MASTER.xlsx opened by kpatel |
| 10 | Oct 15 19:51:40 frontdesk3 audit: user=kpatel copied /srv/records/patients_all.csv (18.4 MB) to /media/kpatel/TRANSFER |
| 11 | Oct 15 19:52:05 frontdesk3 audit: user=kpatel delete /var/log/audit/file_access.log.1 DENIED (permission denied) |
| 12 | Oct 15 19:53:11 frontdesk3 udisks: Unmounted /dev/sdb1 from /media/kpatel/TRANSFER |
Source: Hypothetical device records written for this practice question. The clinic's front desk is staffed from 8:00 a.m. to 5:00 p.m.
Source 4: File listing
$ ls -l /srv/records
-rw-rw-r-- 1 clinic frontdesk 19293184 Oct 15 06:00 patients_all.csv
-rw-r--r-- 1 clinic frontdesk 6120 Oct 15 06:00 schedule_today.csv
-rw-r----- 1 clinic billing 88412 Oct 14 18:30 billing_summary.xlsx
-rw-rw-rw- 1 clinic clinic 40211 Sep 30 09:00 Card_Numbers_MASTER.xlsx
-rwxr-x--- 1 clinic it 1840 Aug 12 15:22 nightly_backup.sh
Source: Hypothetical device records written for this practice question
Source 5: Riverbend Family Clinic workstation policy
Required:
• Staff must lock their screen whenever they leave the front desk.
• Monitors that face the waiting room must have a privacy screen.
Permitted:
• Front-desk staff may open the records of patients they are scheduling or checking in that day.
Prohibited:
• Staff may not connect personal USB storage devices to clinic computers.
• Staff may not send patient information to personal email accounts.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the workstation policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the workstation policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/records (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii). Use the symbolic form of chmod (for example, u, g, o with + or -).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 3 shows evidence of another attack on the clinic's data. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.